Cloud Malware Detection via Multi-Tenant Cluster Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malware detection systems face scalability and resource constraints, leading to decreased performance and high capital outlay due to the need for additional appliances and network downtime, with limited flexibility and scalability in deployment.
Innovation Solution
A subscription-based, cloud-based malware detection system with a multi-tenant architecture that allows multiple subscribers to access a cloud-based object evaluation service, featuring a cluster management system and cloud broker for efficient resource allocation and compliance with performance attributes, enabling scalable and reliable malware detection with reduced capital expenditure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If additional malware detection appliances are installed to handle increased network traffic, then malware detection capability is improved, but capital outlay and network downtime increase
Solution Approach 1:
The patent creates virtual copies of malware detection capabilities through virtual machines that can be rapidly deployed and scaled. Instead of installing physical appliances, the system uses virtualized instances that can be copied and distributed across the network infrastructure, eliminating the need for additional capital expenditure on hardware while maintaining detection capability.
Solution Approach 2:
The patent implements a multi-tenant cloud-based platform that serves multiple organizations simultaneously with a single infrastructure. The malware detection system is designed to be universal, handling different types of network traffic and threats across multiple tenants, thereby reducing the need for separate dedicated appliances for each organization and lowering overall capital outlay.
2Reliability
If additional malware detection appliances are installed to handle increased network traffic, then malware detection capability is improved, but network downtime increases
Solution Approach 1:
The patent implements dynamic scaling of malware detection resources based on real-time network traffic conditions. The virtual machine infrastructure allows the system to automatically adjust detection capacity without manual intervention or network disruption, enabling seamless scaling that maintains continuous operation and eliminates downtime associated with static appliance installations.
Solution Approach 2:
The patent pre-configures virtual malware detection environments that can be rapidly activated when needed. The virtual machines are prepared in advance with necessary detection tools and configurations, allowing them to be deployed immediately when traffic increases or new threats emerge, eliminating the time required for on-site appliance installation and configuration.
3Adaptability or versatility
If malware detection appliances are deployed to provide scalability, then adaptability is improved, but device complexity increases
Solution Approach 1:
The patent introduces a cloud-based management platform as an intermediary that handles the complexity of multi-tenant malware detection operations. This central platform manages resource allocation, tenant isolation, detection policy enforcement, and scaling operations, thereby simplifying the overall system architecture while maintaining high adaptability and deployment flexibility across diverse network environments.
Data Source
AI summary
A cloud-based system is design with multi-tenancy controls for conducting analytics performed on objects submitted by a subscriber. This system features an analysis monitoring service and an analysis selection services. The analysis monitoring service, operating as a first cloud service, includes logic that is configured to collect metadata associated with an operating state for each of a plurality of clusters and generate cluster selection information. The analysis selection service, operating as a second cloud service and communicatively coupled to the analysis monitoring service, is configured to select a cluster of the plurality of clusters to analyze the object for malware based, at least in part, on the cluster selection information provided from the analysis monitoring service.


